CVE-2025-44034HIGH 8.0EPSS p36.4%

CVE-2025-44034CVE-2025-44034

Description

SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController

Scoring

CVSS 3.18.0 (HIGH)
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.46% probability of exploitation · percentile 36.4% · 2026-06-18T12:00:27Z
Published2025-09-16
Last modified2025-11-19

Underlying weaknesses· 1

CWE-89

References

  1. https://github.com/qkdjksfkeg/Security-Collections/blob/main/sqlinjection2.md

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-890%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-44033
CVE
CVE-2025-1958
CVE
CVE-2025-40886
CVE
CVE-2025-6829
CVE
CVE-2025-25914
CVE
CVE-2025-23176
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.